Written by: Xiao Bing
There is a counterintuitive rule in the field of crypto security: Knowing how much Bitcoin someone possesses is sometimes more dangerous than knowing their private key.
On August 16th, hardware wallet manufacturer SafePal issued a security bulletin confirming an authorization flaw in its order query plugin, which led to unauthorized access to the names, email addresses, phone numbers, shipping addresses, and purchase records of approximately 39,798 customers. The affected customers placed orders between March 2, 2025, and April 11, 2026.
SafePal emphasized in the bulletin that private keys, seed phrases, wallet passwords, bank card numbers, and identity document information were not affected. The cold storage architecture operates in a completely isolated environment, separate from e-commerce servers. There is no evidence to suggest that user wallets or funds were directly compromised.
The company also disclosed that it has identified and taken down over 30 phishing websites related to this incident.
Why a Shopping List is More Frightening Than a Password
What the attackers now possess: The real names, mobile phone numbers, email addresses, and home addresses of nearly 40,000 individuals confirmed to have purchased hardware cold wallets.
The value of this data far exceeds that of typical e-commerce platform order leaks. People who buy cold wallets almost certainly hold crypto assets, and likely substantial amounts. Users willing to spend money on dedicated hardware to secure assets are typically not small-time investors holding just a few hundred dollars.
The attackers don't need to hack any device. What they can do includes:
Impersonating SafePal customer service, sending "firmware update notifications" or "device recall notices" containing real order numbers and purchase dates. Because the order information in the email is authentic, users are more likely to believe the entire email is genuine.
Sending physical letters or packages to the user's home address, including forged QR codes or "replacement devices." SafePal specifically warns in its bulletin to "treat any unexpected communications or hardware deliveries referencing SafePal purchase records as suspicious," indicating that such attacks have already occurred or are anticipated.
Cross-referencing leaked addresses, phone numbers, and emails with social media accounts and on-chain addresses to build more complete user profiles. Once it's confirmed that a resident at a particular address holds a significant amount of crypto assets, physical invasion (so-called "wrench attacks") becomes an option.
SafePal itself admits in its FAQ that phishing attacks may appear in various forms such as "phone calls, emails, text messages, letters, refund offers, firmware update requests, and fake customer service communications." The length of this list itself speaks to the severity of the problem.
Three Months of Silence
What is most worth questioning in this incident is the disclosure timeline.
SafePal's FAQ page admits that it received user reports about phishing emails as early as May but initially treated them as "isolated incidents." A comprehensive review of the order system wasn't conducted until July, and the root cause wasn't confirmed and announced until August.
Approximately three months passed between the first report and the public disclosure. During these three months, attackers were already using the leaked data to send phishing emails, and SafePal confirmed it had discovered and taken down over 30 phishing websites. This means users were unknowingly exposed to highly targeted social engineering attacks for months.
SafePal also disclosed a detail: its data-purge routine had stopped running due to a configuration error, causing old order information that should have been deleted after 90 days to remain in the system. This implies the amount of leaked data might be larger than normal. Data that should have been destroyed according to the privacy policy survived due to a configuration bug and was then leaked.
The Security Paradox of Cold Wallets
This SafePal incident exposes a structural contradiction within the hardware wallet industry.
The entire selling point of a cold wallet is security. It protects private keys through physical isolation, preventing hackers from reaching core assets via cyber attacks. This promise, SafePal did fulfill; what leaked was the e-commerce system, not the wallet system.
But cold wallets must be sold through e-commerce channels, and these channels inherently require collecting users' real identity information: name, address, phone number, for logistics and delivery. Once this information is leaked, it precisely marks "who is safeguarding large crypto assets."
Ledger experienced an almost identical incident in 2020: approximately 270,000 customers' names, emails, phone numbers, and addresses were leaked. Following the leak, victims reported numerous highly targeted phishing emails and SIM-swapping attacks. Some users even received death threats. Ledger's CEO later publicly apologized, acknowledging failures in the company's data retention and security practices.
SafePal now faces a replay of the same lesson. The only differences are the smaller scale (39.8k vs. 270k), but the attacker's playbook is exactly the same.
What Should You Do?
SafePal provided standard security advice in its bulletin: Do not share your seed phrase, do not click on unknown links, manually enter the official website address instead of clicking links in emails.
But for affected users, there are several more practical things worth doing.
The most urgent step is to check whether you have received any "firmware update" or "device recall" notifications sent in SafePal's name. If you have already entered your seed phrase on a suspicious page, immediately create a new wallet and transfer your assets. SafePal clearly states in its bulletin that it will never ask for your seed phrase via phone, email, or any other channel.
Go to SafePal's dedicated verification page to check if you are affected using your order number. If confirmed, you can request deletion of your personal information. For the next several months, treat all physical letters and packages mentioning SafePal or cold wallets as suspicious. SafePal explicitly states it will never send physical letters.
If your shipping address is also where you store your crypto assets, seriously evaluate your physical security measures. This might sound like an overreaction, but after the Ledger leak, there were users who faced personal threats because of this very data.
The crypto industry has spent a decade educating users to "secure your private keys." The lessons from SafePal and Ledger show that attackers have long bypassed the private key; they target the person holding it. The moment the information "who is holding crypto assets" is leaked, even the most robust cold storage cannot offer protection.
The weakest link in the security chain has never been the chip or cryptography; it's the human.








